CVE-2018-15328

Severity
7.5HIGH
EPSS
2.2%
top 15.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateMay 14

Description

On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear to the various configuration files.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages16 packages

NVDf5/iworkflow2.2.02.3.0
NVDf5/big-ip_domain_name_system11.2.111.6.3+3
NVDf5/big-ip_access_policy_manager11.2.111.6.3+3
NVDf5/big-ip_local_traffic_manager11.2.111.6.3+3

🔴Vulnerability Details

2
GHSA
GHSA-fggc-gj4v-g5xq: On BIG-IP 142022-05-14
CVEList
CVE-2018-15328: On BIG-IP 142018-12-12

📋Vendor Advisories

1
F5
CVE-2018-15328: On BIG-IP 142018-12-12